CVE Database

CVE-2017-17674CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-918

BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Side Request Forgery (SSRF), or remote code execution (RCE).

CVE-2021-33204CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

In the pg_partman (aka PG Partition Manager) extension before 4.5.1 for PostgreSQL, arbitrary code execution can be achieved via SECURITY DEFINER functions because an explicit search_path is not set.

CVE-2021-20720CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in the KonaWiki2 versions prior to 2.2.4 allows remote attackers to execute arbitrary SQL commands and to obtain/alter the information stored in the database via unspecified vectors.

CVE-2021-20721CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

KonaWiki2 versions prior to 2.2.4 allows a remote attacker to upload arbitrary files via unspecified vectors. If the file contains PHP scripts, arbitrary code may be executed.

CVE-2021-27459CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The webserver of the affected products allows unvalidated files to be uploaded, which an attacker could utilize to execute arbitrary code.

CVE-2020-12061CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-522

An issue was discovered in Nitrokey FIDO U2F firmware through 1.1. Communication between the microcontroller and the secure element transmits credentials in plain. This allows an adversary to eavesdrop the communication and derive the secrets stored in the microcontroller. As a result, the attacker is able to arbitrarily manipulate the firmware of the microcontroller.

CVE-2021-31474CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SolarWinds.Serialization library. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-12213.

CVE-2018-25011CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().

CVE-2018-25014CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-908

A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().

CVE-2020-36328CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVE-2020-36329CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVE-2021-33514CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker via the vulnerable /sqfs/lib/libsal.so.0.0 library used by a CGI application, as demonstrated by setup.cgi?token=';$HTTP_USER_AGENT;' with an OS command in the User-Agent field. This affects GC108P before 1.0.7.3, GC108PP before 1.0.7.3, GS108Tv3 before 7.0.6.3, GS110TPPv1 before 7.0.6.3, GS110TPv3 before 7.0.6.3, GS110TUPv1 before 1.0.4.3, GS710TUPv1 before 1.0.4.3, GS716TP before 1.0.2.3, GS716TPP before 1.0.2.3, GS724TPPv1 before 2.0.4.3, GS724TPv2 before 2.0.4.3, GS728TPPv2 before 6.0.6.3, GS728TPv2 before 6.0.6.3, GS752TPPv1 before 6.0.6.3, GS752TPv2 before 6.0.6.3, MS510TXM before 1.0.2.3, and MS510TXUP before 1.0.2.3.

CVE-2020-25409CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters.

CVE-2020-28900CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-345

Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh.

CVE-2020-28901CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt component installation in cmd_subsys.php.

CVE-2020-28902CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php.

CVE-2020-28904CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-269

Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation as nagios via installation of a malicious component containing PHP code.

CVE-2020-28907CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-295

Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to download of an untrusted update package in upgrade_to_latest.sh.

CVE-2020-28908CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to nagios.

CVE-2020-28910CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-732

Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of symlinks, which are mishandled in getprofile.sh.

CVE-2021-32075CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Re-Logic Terraria before 1.4.2.3 performs Insecure Deserialization.

CVE-2021-20426CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196313.

CVE-2019-12348CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in zzcms 2019. SQL Injection exists in user/ztconfig.php via the daohang or img POST parameter.

CVE-2021-29300CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

The @ronomon/opened library before 1.5.2 is vulnerable to a command injection vulnerability which would allow a remote attacker to execute commands on the system if the library was used with untrusted input.

CVE-2021-30188CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.

CVE-2021-30189CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow.

CVE-2021-30190CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.

CVE-2021-30192CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.

CVE-2021-30193CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write.

CVE-2020-10064CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

Improper Input Frame Validation in ieee802154 Processing. Zephyr versions >= v1.14.2, >= v2.2.0 contain Stack-based Buffer Overflow (CWE-121), Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3gvq-h42f-v3c7

CVE-2020-13601CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

Possible read out of bounds in dns read. Zephyr versions >= 1.14.2, >= 2.3.0 contain Out-of-bounds Read (CWE-125). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-mm57-9hqw-qh44

CVE-2021-25944CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

Prototype pollution vulnerability in 'deep-defaults' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.

CVE-2021-25946CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

Prototype pollution vulnerability in `nconf-toml` versions 0.0.1 through 0.0.2 allows an attacker to cause a denial of service and may lead to remote code execution.

CVE-2021-33574CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.

CVE-2021-33575CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

The Pixar ruby-jss gem before 1.6.0 allows remote attackers to execute arbitrary code because of the Plist gem's documented behavior of using Marshal.load during XML document processing.

CVE-2021-22160CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-347

If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if the algorithm of the presented token is set to "none". This allows an attacker to connect to Pulsar instances as any user (incl. admins).

CVE-2021-33470CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

COVID19 Testing Management System 1.0 is vulnerable to SQL Injection via the admin panel.

CVE-2021-21986CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability plug-ins. A malicious actor with network access to port 443 on vCenter Server may perform actions allowed by the impacted plug-ins without authentication.

CVE-2021-25945CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

Prototype pollution vulnerability in 'js-extend' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.

CVE-2019-25029CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an application passes unsafe user supplied data (forms, cookies, HTTP headers etc.) to a system shell. In this attack, the attacker-supplied operating system commands are usually executed with the privileges of the vulnerable application. Command injection attacks are possible largely due to insufficient input validation.

CVE-2021-22731CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-640

Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSESP* V8.21 and prior which could cause an unauthorized password change through HTTP / HTTPS when basic user information is known by a remote attacker.

CVE-2021-22737CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

Insufficiently Protected Credentials vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthorized access of when credentials are discovered after a brute force attack.

CVE-2021-22738CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-327

Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthorized access when credentials are discovered after a brute force attack.

CVE-2021-22891CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-862

A missing authorization vulnerability exists in Citrix ShareFile Storage Zones Controller before 5.7.3, 5.8.3, 5.9.3, 5.10.1 and 5.11.18 may allow unauthenticated remote compromise of the Storage Zones Controller.

CVE-2021-33590CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

GattLib 0.3-rc1 has a stack-based buffer over-read in get_device_path_from_mac in dbus/gattlib.c.

CVE-2021-31535CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code. The libX11 XLookupColor request (intended for server-side color lookup) contains a flaw allowing a client to send color-name requests with a name longer than the maximum size allowed by the protocol (and also longer than the maximum packet size for normal-sized packets). The user-controlled data exceeding the maximum size is then interpreted by the server as additional X protocol requests and executed, e.g., to disable X server authorization completely. For example, if the victim encounters malicious terminal control sequences for color codes, then the attacker may be able to take full control of the running graphical session.

CVE-2021-37608CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apache OFBiz version 17.12.07 and prior versions. Upgrade to at least 17.12.08 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12297.

CVE-2020-27847CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-228

A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation. This flaw allows an attacker to bypass SAML authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. This flaw affects dex versions before 2.27.0.

CVE-2021-20236CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by sending crafted topic subscription requests and then unsubscribing. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVE-2020-15782CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions < V4.5.0), SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions < V2.9.2), SIMATIC S7-1500 Software Controller (All versions < V21.9), SIMATIC S7-PLCSIM Advanced (All versions < V4.0), SINAMICS PERFECT HARMONY GH180 Drives (Drives manufactured before 2021-08-13), SINUMERIK MC (All versions < V6.15), SINUMERIK ONE (All versions < V6.15). Affected devices are vulnerable to a memory protection bypass through a specific operation. A remote unauthenticated attacker with network access to port 102/tcp could potentially write arbitrary data and code to protected memory areas or read sensitive data to launch further attacks.

← PreviousPage 399 / 7034Next →